Threat reportMalwareTL-2026-1344

AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)

highACTIVE

AtlasRAT: Four-Stage In-Memory Loader Chain Delivers (TL-2026-1344), also tracked as Atlas RAT, is a high-severity malware campaign, first published 2026-07-15 and last reviewed 2026-07-30. It is attributed to Void Arachne (China) with medium confidence, affects Generic Windows endpoints (consumer/enterprise), maps to 51 MITRE ATT&CK techniques (T1005, T1008, T1021.001), and is covered by 9 detection rules and 61 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
51MITRE ATT&CK
Actors
1Void Arachne
Detection rules
9SPL · KQL · Sigma
IOCs
61Indicators of compromise

Key facts for TL-2026-1344

Threat ID
TL-2026-1344
Also known as
Atlas RAT, AtlasCross
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Void Arachne
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
consumer, technology, finance, government administration
Target regions
china, japan, malaysia, philippines, thailand, indonesia, singapore, india
Detection rules
9
Indicators of compromise
61
Updates
2026-07-30 · 2 updates · revalidated 2× · latest source

Malware and tooling in AtlasRAT: Four-Stage In-Memory Loader Chain Delivers

Malware and tooling: AtlasRAT, MainDll.dll

How AtlasRAT: Four-Stage In-Memory Loader Chain Delivers works

AhnLab ASEC documented AtlasRAT, a modular remote access trojan delivered through a four-stage, largely in-memory loader chain that begins with a Delphi executable disguised as "AGE Flash Player." The final payload uses ChaCha20-over-TLS C2 communication with a spoofed Microsoft certificate, injects into WeChat, performs offline keylogging, and enumerates 33 security products; ASEC tracked 43 active AtlasRAT C2 servers as of 2026-06-09 and found partial marker overlap ("By@V<") with the Silver Fox threat actor's related "Atlas RAT"/AtlasCross campaigns, though the two variants use different handshake strings (BFuck vs. SFuck).

AtlasRAT is a commercial-grade remote access trojan tracked by AhnLab ASEC in a report titled "Not Every Fox is Silver: Inside an AtlasRAT Loader Chain" (2026-07-15). The infection begins with a Delphi-compiled executable masquerading as an "AGE Flash Player" installer (Stage 1). This dropper decrypts and loads an embedded PE image (Stage 2) entirely in memory, which in turn reconstructs downloader shellcode from eight separately encrypted fragments (Stage 3). The shellcode reflectively maps and executes MainDll.dll, a 32-bit RAT payload, via a technique ASEC labels ServiceRun (Stage 4). No stage other than the initial dropper is written to disk, minimizing forensic artifacts and defeating static AV scanning of intermediate stages.

Once resident, AtlasRAT establishes command-and-control over TLS to 150.158.50.175:443, opening every session with an 8-byte handshake marker "BFuck\0\0\0" (hex 42 46 75 63 6b 00 00 00). The TLS session itself is wrapped in an additional application-layer ChaCha20 stream cipher, and the certificate presented is self-signed but spoofs the subject "CN=update.microsoft.com, O=Microsoft Corporation, C=US" (SHA-256 fingerprint 3f152103ea35c0f7feb205651a91e3c946b8057d1ea6f046ffc44fa611fd0267) to blend into HTTPS traffic logs and evade naive certificate-pinning defenses. ASEC's telemetry identified 43 active AtlasRAT C2 servers as of 2026-06-09, indicating an operationally mature, multi-tenant or affiliate-style infrastructure footprint consistent with a commercially distributed RAT rather than a single-operator tool.

The final-stage payload is built around a modular plugin architecture. Observed capabilities include offline/buffered keylogging (keystrokes cached locally and exfiltrated in batches rather than streamed live, reducing detectable network chatter), DLL injection into WeChat.exe to intercept or manipulate the popular Chinese messaging client, and a security-product inventory routine that fingerprints the presence of 33 distinct security executables on the host — behavior consistent with pre-attack reconnaissance intended to select an evasion profile or abort execution on well-defended hosts. General process/file enumeration and system information collection round out the plugin set. Persistence markers and configuration state are dropped to C:\Users\Public\Documents\ using the filenames offline.ini, MODIf.html, AtlasPro.ini, and Wxfun.dll, giving defenders concrete host-based indicators even though the loader chain itself is fileless.

ASEC's analysis explicitly compares AtlasRAT to previously reported "Silver Fox" activity. Silver Fox (also tracked as Void Arachne, SwimSnake, UTG-Q-1000, and "The Great Thief of Valley") is a Chinese-origin threat actor with a multi-year lineage running from Gh0st RAT derivatives through ValleyRAT, Gh0stCringe, HoldingHands RAT, and Winos 4.0 to the current "Atlas RAT" / AtlasCross family. Independent reporting (Hexastrike, The Hacker News, March 2026) documents a related Silver Fox campaign delivering an "Atlas RAT" via a triple-nested Setup Factory installer trojanizing a stolen Autodesk binary, dynamically resolving APIs via PEB walking, decrypting an embedded Gh0st RAT configuration, and downloading second-stage shellcode over raw TCP (port 9899) to a C2 domain bifa668[.]com (registered 2025-10-27, resolving to 61.111.250.139, ASN 138195 MOACK.Co.LTD, South Korea) fronted by nameservers a.share-dns.com/b.share-dns.net. That campaign's handshake, "SFuck\0\0\0" (hex 53 46 75 63 6b 00 00 00), differs from AtlasRAT's "BFuck" marker but the two samples share the distinct "By@V<" internal marker string, and both ultimately reflectively load a RAT DLL named/labeled as part of an "Atlas" family — the basis for ASEC's assessment of partial overlap without full identity. The related Silver Fox campaign used eleven brand-impersonating delivery domains (Zoom, Signal, Telegram, Surfshark VPN, Microsoft Teams, QuickQ VPN, UltraViewer, Trezor, KeFuBao, WangWang, plus one unattributed) registered in a single wave on 2025-10-27, code-signed installers abusing a stolen Extended Validation certificate issued to a Vietnamese entity (DUC FABULOUS CO., LTD, Hanoi), and native CLR-hosted PowerShell execution that disables AMSI, ETW, Constrained Language Mode, and ScriptBlock logging without ever spawning powershell.exe. Both the AtlasRAT and the related Silver Fox Atlas RAT lineage specifically target Chinese-speaking users and enumerate/disable Chinese security products (360 Total Security/360 Safe, Huorong, Kingsoft, QQ PC Manager), and both inject into or monitor WeChat.

This skeleton is scoped strictly to the ASEC-documented AtlasRAT sample and its 43-server C2 tracking; the related Silver Fox/AtlasCross infrastructure (bifa668[.]com, the eleven typosquat domains, and the stolen Autodesk/Setup Factory delivery chain) is documented here as corroborating attribution/overlap context, sourced independently from Hexastrike and The Hacker News reporting on the broader Silver Fox campaign active November 2025–March 2026.

MITRE ATT&CK techniques used in TL-2026-1344

Collection

T1005 Data from Local System; T1056 Input Capture; T1074.001 Data Staged: Local Data Staging

Command and Control

T1008 Fallback Channels; T1071.001 Application Layer Protocol: Web Protocols; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding; T1571 Non-Standard Port; T1573.001 Encrypted Channel: Symmetric Cryptography

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1563.002 Remote Service Session Hijacking: RDP Hijacking

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.001 Masquerading: Invalid Code Signature; T1036.005 Match Legitimate Resource Name or Location; T1055.001 Process Injection: Dynamic-link Library Injection; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading

Persistence

T1037.001 Logon Script (Windows); T1053.005 Scheduled Task/Job: Scheduled Task; T1197 BITS Jobs; T1543.003 Create or Modify System Process: Windows Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Exfiltration

T1041 Exfiltration Over C2 Channel

Credential Access

T1056.001 Input Capture: Keylogging

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518.001 Security Software Discovery

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1106 Native API; T1129 Shared Modules; T1204.002 User Execution: Malicious File

defense-impairment

T1112 Modify Registry; T1553.002 Code Signing; T1553.006 Code Signing Policy Modification; T1685 Disable or Modify Tools; T1685.001 Disable or Modify Windows Event Log

Initial Access

T1195 Supply Chain Compromise; T1195.002 Compromise Software Supply Chain; T1566 Phishing; T1566.002 Phishing: Spearphishing Link

Impact

T1529 System Shutdown/Reboot

Privilege Escalation

T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.001 Develop Capabilities: Malware; T1588.003 Obtain Capabilities: Code Signing Certificates

Affected products and versions in AtlasRAT: Four-Stage In-Memory Loader Chain Delivers

  • Generic — Windows endpoints (consumer/enterprise)
    Vulnerable versions: Windows 10; Windows 11; Windows Server (general)

Remediation for AtlasRAT: Four-Stage In-Memory Loader Chain Delivers

Immediate actions

  • Block C2 IPs 150.158.50.175, 108.187.7.84, 116.204.169.70, 143.92.32.49, 143.92.32.65, 143.92.32.72, and 61.111.250.139 at perimeter firewall/proxy
  • Sinkhole or block DNS resolution for bifa668.com and the eleven Silver Fox typosquat delivery domains
  • Hunt for host artifacts offline.ini, MODIf.html, AtlasPro.ini, and Wxfun.dll under C:\Users\Public\Documents\
  • Revoke trust for/flag the stolen Extended Validation code-signing certificate issued to DUC FABULOUS CO., LTD
  • Alert on TLS sessions opening with the 8-byte handshake markers 42 46 75 63 6b 00 00 00 ("BFuck") or 53 46 75 63 6b 00 00 00 ("SFuck")

Workarounds

  • Block execution of Setup Factory (SFX 7.0/8.0) extracted binaries from %TEMP%_ir_sf[7|8]_temp_0 paths via application control policy

Longer-term hardening

  • Deploy EDR with in-memory/reflective-loading detection (ETW-based, not signature-based, since payload is fileless after Stage 1)
  • Enforce application allowlisting to block unsigned/renamed installer executables masquerading as Flash Player or Autodesk products
  • Monitor and alert on DLL injection targeting WeChat.exe and other messaging clients
  • Deploy TLS certificate-transparency / JA3-style fingerprinting to catch spoofed 'update.microsoft.com' self-signed certs
  • User awareness training on fake VPN/messaging-app installers as a Silver Fox delivery vector

Timeline of AtlasRAT: Four-Stage In-Memory Loader Chain Delivers

  • The Extended Validation code-signing certificate for "DUC FABULOUS CO., LTD" (Hanoi, Vietnam) later abused across Silver Fox's related Atlas RAT installers is issued; per Hexastrike the certificate remains valid through 2027-05-15.
  • Silver Fox registers eleven brand-impersonating typosquat delivery domains (Zoom, Signal, Telegram, Surfshark, Microsoft Teams, and others) plus the bifa668[.]com C2 domain in a single registration wave, per Hexastrike analysis of the related Atlas RAT campaign.
  • First identified related Atlas RAT standalone executables appear, the start of a four-month wave of roughly twenty Silver Fox Atlas-family DLL samples observed by Hexastrike.
  • Silver Fox's AtlasCross RAT campaign targeting Chinese-speaking users is observed extending across Japan, Malaysia, the Philippines, Thailand, Indonesia, Singapore, and India.
  • Tax-themed phishing lures targeting Indian users are reported (eSentire, cited via The Hacker News) as part of the broader Silver Fox Atlas campaign.
  • Approximate start of ASEC's 180-day VirusTotal retrohunt window (per ASEC's English-language follow-up report) that surfaced the 146 AtlasRAT samples.
  • The Hacker News publishes reporting on Silver Fox's AtlasCross RAT campaign and fake domains.
  • Infection timestamp recorded inside a dropped Silver Fox Atlas RAT configuration file, per Hexastrike's sample analysis.
  • Hexastrike observes the newest related Silver Fox Atlas RAT payload sample, one day before publishing its analysis.
  • Dark Lab publishes analysis of Silver Fox's dual-pronged ValleyRAT distribution strategy, documenting continued activity by the actor cluster circumstantially linked to AtlasRAT.
  • Hexastrike publishes detailed technical analysis "Trust the Tunnel, Get the Trojan," documenting the Setup Factory/stolen-Autodesk loader chain, SFuck handshake, and bifa668[.]com C2 infrastructure.
  • cybersecuritynews.com publishes coverage of Silver Fox's stolen EV code-signing certificate abuse (DUC FABULOUS CO.,LTD, thumbprint 2C1D12F8BBE0827400A8440AF74FFFA8DCC8097C) in the AtlasCross RAT campaign.
  • Persistence86.dll PDB path references build/version labels 'atlasPro验证版2026.6.2' / 'atlasPro Trial Version 2026.6.2', confirming the persistence/UAC-bypass module ships from the same versioned builder pipeline as MainDll.dll.
  • AhnLab ASEC's telemetry records 43 active AtlasRAT command-and-control servers, the infrastructure-scale data point cited in the eventual ASEC report.
  • AhnLab ASEC publishes "Not Every Fox is Silver: Inside an AtlasRAT Loader Chain," documenting the four-stage in-memory loader, BFuck handshake, spoofed Microsoft certificate, WeChat DLL injection, offline keylogging, 33-product security enumeration, and partial marker overlap with Silver Fox's Atlas RAT variant.
  • ASEC's 180-day retrospective VirusTotal hunt surfaces 146 unique AtlasRAT-family samples (x86/x64 builder variants), confirming sustained active distribution rather than an isolated incident.
  • AhnLab ASEC publishes a follow-up AtlasRAT analysis, identifying the same bifa668.com C2 domain and Wxfun.dll WeChat-injection tradecraft as the 2026-07-15 report, delivered via a trojanized 'AGE Flash Player' installer (FlashPlay.exe).

Update history for TL-2026-1344

Sources cited for AtlasRAT: Four-Stage In-Memory Loader Chain Delivers

Detection coverage for TL-2026-1344

As of 2026-07-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1344 across Splunk SPL, Microsoft KQL and Sigma, covering 61 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
61 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats